CVE-2024-52427

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vollstart:event_tickets_with_ticket_scanner:*:*:*:*:*:wordpress:*:*

History

20 Nov 2024, 15:29

Type Values Removed Values Added
References () https://patchstack.com/database/vulnerability/event-tickets-with-ticket-scanner/wordpress-event-tickets-with-ticket-scanner-plugin-2-3-11-remote-code-execution-rce-vulnerability?_s_id=cve - () https://patchstack.com/database/vulnerability/event-tickets-with-ticket-scanner/wordpress-event-tickets-with-ticket-scanner-plugin-2-3-11-remote-code-execution-rce-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:vollstart:event_tickets_with_ticket_scanner:*:*:*:*:*:wordpress:*:*
First Time Vollstart event Tickets With Ticket Scanner
Vollstart
CVSS v2 : unknown
v3 : 9.9
v2 : unknown
v3 : 8.8
CWE CWE-94

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un motor de plantillas en Saso Nikolov Event Tickets con Ticket Scanner permite la inyección de Server Side Include (SSI). Este problema afecta a Event Tickets con Ticket Scanner: desde n/a hasta 2.3.11.

18 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-18 15:15

Updated : 2024-11-20 15:29


NVD link : CVE-2024-52427

Mitre link : CVE-2024-52427

CVE.ORG link : CVE-2024-52427


JSON object : View

Products Affected

vollstart

  • event_tickets_with_ticket_scanner
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine